16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

Chronological Source Flow
Back

AI Fusion Summary

A use-after-free bug in the Linux KVM hypervisor, identified as CVE-2026-53359 and dubbed Januscape, allows guest virtual machines to escape to the host. This flaw exists within the shadow MMU code shared by Intel and AMD x86 systems, enabling the corruption of the host kernel's shadow-page state. While a public proof-of-concept causes the host to panic, researchers claim a separate, unreleased exploit exists. The vulnerability has remained present in the system for sixteen years.
Community Comments
Loading updates...
0